Impact
A flaw in visitor to submit multiple appointments to a time slot that has already reached its capacity, bypassing the capacity check that the plugin is meant to enforce. This allows an attacker to book unavailable slots, creating overlap and scheduling errors that ultimately vulnerability is a logical error in server‑side validation, not a denial of service but an integral policy violation that affects integrity and availability of the booking resource.
Affected Systems
WordPress sites that use the Appointment Hour Booking plugin version below 1.5.95 are impacted. The plugin vendor is listed simply as Appointment Hour Booking; no other specific vendor names are identified. Users of earlier releases should verify their plugin version and apply any upgrades as soon as possible.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as moderate. 1% indicates a low likelihood of exploitation at present. The vulnerability is not currently in the CISA KEV catalog. Because authentication is not required to submit the booking, the attack vector is internet-facing and can be triggered by any remote host that can reach the site. An attacker would craft a booking request targeting an already full slot, and the server would accept it due to the missing capacity check, resulting in the over‑booking of the slot.
OpenCVE Enrichment